Chinese State Hackers Breached the Fed, NASA, DOJ, and Senate
The DOJ and FBI confirmed on August 26 that PRC state-sponsored hackers breached the Federal Reserve, NASA, DOJ, and the U.S. Senate using two platforms active since at least 2018. No damage scope was disclosed.

The DOJ confirmed PRC-backed group QTFY penetrated the Federal Reserve and six other U.S. agencies. No damage scope has been disclosed.
Key takeaways
- The DOJ and FBI seized three domains powering QScan and QTRouter, two platforms used by PRC state-sponsored hackers to breach the Federal Reserve, NASA, DOJ, the U.S. Senate, and three other federal agencies, active since at least 2018.
- QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company, sold botnet access to China's Ministry of State Security and People's Liberation Army. The U.S. government has disclosed no details on what data was accessed or how long the intrusions lasted.
- This is the fourth consecutive year the FBI has disrupted a major PRC hacking operation, confirming a systematic, persistent campaign against U.S. critical infrastructure with no end to the underlying attack surface in sight.
The Department of Justice and FBI announced Wednesday, August 26 the court-authorized seizure of three domains powering two hacking platforms, QScan and QTRouter, operated by a PRC state-sponsored group designated QTFY. Confirmed victims include the Federal Reserve, NASA, the Department of Justice, the U.S. Senate, the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health. QTFY has been active since at least 2018.
The DOJ disclosed zero details on what data was accessed, what systems were touched inside those agencies, or how long QTFY maintained access. That silence is itself the operative fact.
How the Platforms Worked
QTFY was employed by China-based Nanjing Xinjiuwei Network Technology Company. Its paying customers included China's Ministry of State Security and the People's Liberation Army, per court documents unsealed in the Southern District of California.
QScan automatically scanned and infected IoT devices worldwide. Those compromised devices fed into QTRouter, an obfuscation network routing attack traffic through systems in more than 130 countries. The result: intrusions appeared to originate locally near target networks rather than from China. Because the seized domains were hard-coded into both malware packages for authentication and communication, seizing them rendered both platforms inoperable immediately.
"For nearly a decade, QTFY has exploited software vulnerabilities to launch cyberattacks against U.S. critical infrastructure," said Brett Leatherman, FBI Cyber Division Assistant Director, in a video statement. Attorney General Todd Blanche added: "State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted."
A joint FBI/NSA cybersecurity advisory with indicators of compromise based on QTFY activity dating to at least 2018 was published the same day, referenced in the DOJ press release.
The Fed Is a Honeypot, Not a Fortress
The Federal Reserve holds the master ledger of dollar-denominated obligations. Foreign adversaries with read access to Fed systems could monitor liquidity operations, reserve movements, or regulatory communications in ways that would give geopolitical influence invisible to markets. The DOJ confirmed intrusion. It refused to say what was seen.
Volt Typhoon (2023), Flax Typhoon (2024), Mustang Panda/PlugX (2025), and now QTFY (2026) represent four consecutive years of PRC botnet disruptions, confirming a systematic, persistent campaign rather than isolated incidents. Each takedown renders specific infrastructure inoperable. No takedown closes the underlying attack surface: centralized, internet-connected government systems that must stay online to function.
The contrast with Bitcoin's architecture is direct. Bitcoin's consensus runs on tens of thousands of nodes globally. There is no central domain to seize, no hard-coded authentication endpoint to shut down, no master ledger to exfiltrate.
A state-sponsored actor cannot render the network inoperable by taking three domains offline. The DOJ press release makes that advantage concrete, not theoretical.
Every sat held at a custodian tied to regulated U.S. financial infrastructure is one hop from a network a Nanjing front company had access to. Ongoing U.S. government action against Chinese hardware and software in critical American infrastructure and this QTFY disruption point to the same exposure: critical American systems, financial and otherwise, are deeply penetrated and the remediation is piecemeal.
The falsifiable version of this argument: if the DOJ eventually discloses that QTFY touched only peripheral, non-monetary systems at the Federal Reserve, and all seven agencies produce forensic audits confirming zero exfiltration of sensitive financial or surveillance data, the severity argument weakens considerably. That disclosure has not come. The government has every incentive to minimize. If this is what was made public, the rest is likely worse.
What to Watch
The FBI/NSA advisory published August 26 carries indicators of compromise going back to 2018. Any organization, financial or otherwise, that has not audited exposure against those IOCs should treat that as urgent.
Beijing has not officially responded, consistent with its pattern across prior attribution events. No timeline for a damage assessment from the seven named agencies has been set. The DOJ's silence on scope is the number to watch: if a disclosure comes, it will either narrow the threat or confirm it.
Sources
Frequently Asked Questions
Unknown. The DOJ press release confirms "computer intrusion activity" at the Federal Reserve but explicitly does not disclose what systems were accessed, what data was exfiltrated, or how long QTFY maintained a presence. No forensic audit has been released.
QTFY operated as a commercial "hackers for hire" platform, selling botnet access and intrusion infrastructure to paying clients including China's Ministry of State Security and PLA. Volt Typhoon (disrupted 2023) and Flax Typhoon (disrupted 2024, hundreds of thousands of infected IoT devices) were separate PRC-backed groups with different operational models. QTFY is the newest publicly disclosed group in what is now a four-year consecutive run of major PRC botnet disruptions.
The operational answer is self-custody. Bitcoin held at a custodian with exposure to regulated U.S. financial infrastructure sits inside the same network architecture a foreign state actor just demonstrated it can penetrate and persist in undetected. Holding your own keys, on hardware not connected to that infrastructure, removes that hop from the threat model entirely. Running your own node extends that logic to the verification layer.


